Systems and methods for creating and presenting relationships within information technology data
In one aspect, a computing system including a processor in communication with at least one memory may be provided. The processor may be configured to: (i) connect to a plurality of data sources in a nodal network including a plurality of nodes; (ii) determine, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes; (iii) generate, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships; (iv) analyze each relationship of the determined relationships to determine at least one threat; (v) determine at least one solution for the at least one threat; and/or (vi) cause display of the at least one threat and the at least one solution.
1 . A data security protocol computing system configured to identify potential data security threats and deploy solutions to the potential data security threats, the data security protocol computing system comprising a processor in communication with at least one memory, the processor configured to:
connect to a plurality of data sources in a nodal network comprising a plurality of nodes, wherein each data source of the plurality of data sources is associated with a node type of a plurality of node types and comprises at least one node of the plurality of nodes;
determine, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes;
generate, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships as an edge of a plurality of edges;
cause a machine learning model to analyze each relationship of the determined relationships, wherein the machine learning model is trained in a plurality of stages, wherein each stage of the plurality of stages is associated with one or more training sets comprising at least one of previously-deployed solutions to threats, threats, or non-threats;
receive an output from the machine learning model comprising at least one data security threat associated with at least one node of the plurality of nodes, at least one edge of the plurality of edges between the at least one node and a different node of the plurality of nodes, and at least one data security solution, the at least one data security solution associated with the at least one data security threat and comprising at least one of a software patch or a new version of software;
cause display of the at least one edge in a first display format at a client computing device, the first display format associated with the at least one data security threat;
automatically implement the at least one data security solution based on the output from the machine learning model; and
update display of the at least one edge at the client computing device from the first display format to a second display format, the second display format associated with the at least one data security solution being implemented.
2 . The data security protocol computing system of claim 1 , wherein the processor is further configured to:
cause display of each node of the plurality of nodes and each edge of the plurality of edges;
receive an input selecting at least one of i) the at least one node of the plurality of nodes and ii) the at least one edge of the plurality of edges; and
cause display of at least one non-compliance and at least one solution associated with the input.
3 . The data security protocol computing system of claim 1 , wherein the processor is configured to:
cause display of each node of the plurality of nodes and each edge of the plurality of edges; and
modify display of each edge of the plurality of edges associated with the at least one data security threat in order to communicate the at least one edge of the plurality of edges that is associated with the at least one data security threat.
4 . The data security protocol computing system of claim 1 , wherein the processor is further configured to:
determine one or more nodes of the plurality of nodes accessible by a user of the data security protocol computing system based upon a security level associated with the user; and
cause display of only the one or more nodes accessible by the user and any threats associated therewith.
5 . The data security protocol computing system of claim 1 , wherein the machine learning model comprises a neural network, and wherein the processor is further configured to:
create a first training set of the one or more training sets comprising a plurality of threats including the at least one data security threat;
train the neural network in a first stage of the plurality of stages using the first training set;
create a second training set of the one or more training sets comprising the first training set and non-threats that are incorrectly identified as threats after the first stage of training; and
train the neural network in a second stage of the plurality of stages using the second training set.
6 . The data security protocol computing system of claim 1 , wherein the plurality of node types includes at least one of: assets, representing at least one computing device, policies, representing company policies, controls, representing data security controls, and data security protocols, representing defined data security protocols.
7 . The data security protocol computing system of claim 1 , wherein the processor is further configured to cause display of the mapping including each node and each edge at the client computing device.
8 . The data security protocol computing system of claim 7 , wherein the processor is further configured to:
receive an input at the client computing device, the input selecting a node; and
filter display of the mapping as including edges associated with the node and not other edges.
9 . The data security protocol computing system of claim 8 , wherein the processor is further configured to cause display of node data associated with the node based upon the input, the node data comprising at least one of an asset name associated with the node or an asset type associated with the node.
10 . A computer-implemented method implemented by a computing system including a processor in communication with at least one memory, the method comprising:
connecting to a plurality of data sources in a nodal network comprising a plurality of nodes, wherein each data source of the plurality of data sources is associated with a node type of a plurality of node types and comprises at least one node of the plurality of nodes;
determining, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes;
generating, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships as an edge of a plurality of edges;
causing a machine learning model to analyze each relationship of the determined relationships, wherein the machine learning model is trained in a plurality of stages, wherein each stage of the plurality of stages is associated with one or more training sets comprising at least one of previously-deployed solutions to threats, threats, and non-threats;
receiving an output from the machine learning model comprising at least one data security threat associated with at least one node of the plurality of nodes, at least one edge of the plurality of edges between the at least one node and a different node of the plurality of nodes, and at least one data security solution, the at least one data security solution associated with the at least one data security threat and comprising at least one of a software patch or a new version of software;
causing display of the at least one edge in a first display format at a client computing device, the first display format associated with the at least one data security threat;
automatically implementing the at least one data security solution based on the output from the machine learning model; and
updating display of the at least one edge at the client computing device from the first display format to a second display format, the second display format associated with the at least one data security solution being implemented.
11 . The computer-implemented method of claim 8 further comprising:
causing display of each node of the plurality of nodes and each edge of the plurality of edges;
receiving an input selecting at least one of i) at least one node of the plurality of nodes and ii) the at least one edge of the plurality of edges; and
causing display of at least one non-compliance and at least one solution associated with the input.
12 . The computer-implemented method of claim 10 , further comprising:
causing display of each node of the plurality of nodes and each edge of the plurality of edges; and
modifying display of each edge of the plurality of edges associated with the at least one data security threat in order to communicate the at least one edge of the plurality of edges that is associated with the at least one data security threat.
13 . The computer-implemented method of claim 10 further comprising:
determining one or more nodes of the plurality of nodes accessible by a user of the computing system based upon a security level associated with the user; and
causing display of only the one or more nodes accessible by the user and any threats associated therewith.
14 . The computer-implemented method of claim 10 , wherein the machine learning model comprises a neural network, and wherein the method further comprises:
creating a first training set of the one or more training sets comprising a plurality of threats including the at least one data security threat;
training the neural network in a first stage of the plurality of stages using the first training set;
creating a second training set of the one or more training sets comprising the first training set and non-threats that are incorrectly identified as threats after the first stage of training; and
training the neural network in a second stage of the plurality of stages using the second training set.
15 . The computer-implemented method of claim 10 , wherein the plurality of node types includes at least one of: assets, representing at least one computing device, policies, representing company policies, controls, representing data security controls, and data security protocols, representing defined data security protocols.
16 . At least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon, wherein when executed by a computing system including at least one processor in communication with at least one memory device, the computer-executable instructions cause the at least one processor to:
connect to a plurality of data sources in a nodal network comprising a plurality of nodes, wherein each data source of the plurality of data sources is associated with a node type of a plurality of node types and comprises at least one node of the plurality of nodes;
determine, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes;
generate, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships as an edge of a plurality of edges;
cause a machine learning model to analyze each relationship of the determined relationships, wherein the machine learning model is trained in a plurality of stages, wherein each stage of the plurality of stages is associated with one or more training sets comprising at least one of previously-deployed solutions to threats, threats, and non-threats;
receive an output from the machine learning model comprising at least one data security threat associated with at least one node of the plurality of nodes, at least one edge of the plurality of edges between the at least one node and a different node of the plurality of nodes, and at least one data security solution, the at least one data security solution associated with the at least one data security threat and comprising at least one of a software patch or a new version of software;
cause display of the at least one edge in a first display format at a client computing device, the first display format associated with the at least one data security threat;
automatically implement the at least one data security solution based on the output from the machine learning model; and
update display of the at least one edge at the client computing device from the first display format to a second display format, the second display format associated with the at least one data security solution being implemented.
17 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the computer-executable instructions further cause the processor to:
cause display of each node of the plurality of nodes and each edge of the plurality of edges;
receive an input selecting at least one of i) at least one node of the plurality of nodes and ii) the at least one edge of the plurality of edges; and
cause display of at least one non-compliance and at least one solution associated with the input.
18 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the computer-executable instructions further cause the processor to:
cause display of each node of the plurality of nodes and each edge of the plurality of edges; and
modify display of each edge of the plurality of edges associated with the at least one data security threat in order to communicate the at least one edge of the plurality of edges that is associated with the at least one data security threat.
19 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the computer-executable instructions further cause the processor to:
determine one or more nodes of the plurality of nodes accessible by a user of the computing system based upon a security level associated with the user; and
cause display of only the one or more nodes accessible by the user and any threats associated therewith.
20 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the machine learning model comprises a neural network, and wherein the computer-executable instructions further cause the processor to:
create a first training set of the one or more training sets comprising a plurality of threats including the at least one data security threat;
train the neural network in a first stage of the plurality of stages using the first training set;
create a second training set of the one or more training sets comprising the first training set and non-threats that are incorrectly identified as threats after the first stage of training; and
train the neural network in a second stage of the plurality of stages using the second training set.